A cybercriminal group that compromised a cybersecurity vendor’s cloud-based resources attempted to blackmail the company by blackmailing their families, the company said.
Dragos, an operational technology (OT) security specialist, said on May 8 that attackers compromised new hires’ email accounts before their onboarding date.
Ransomware Details: Ransomware deployment time reduced by 94%.
They then used the employee’s personal information to impersonate the employee and complete basic onboarding, according to the vendor’s report on the incident. This gave him access to his company’s SharePoint account and contract management system, but nothing more.
However, after failing to deploy a ransomware payload and steal sensitive information, the group appears to have attempted to extort Dragos executives to avoid disclosure.
None of the Dragos officials responded, but the group repeatedly tried to increase pressure, contacting several publicly known Dragos employees and using family information to try and coerce them into responding.
“The cybercriminals’ texts indicate that they knew the names of the families of known TTP Dragos executives, so they investigated the family details. I was referring to it,” the report notes.
“Additionally, during this time, cybercriminals contacted senior Dragos employees via personal email.
Dragos co-founder and CEO Robert Lee shared the details on Twitter.
“Criminals were obviously annoyed that we didn’t try to contact them.” he tweeted. “I never had the option to pay. They continued to call me and threaten my family and many of the employees’ families by name.”
Ultimately, the vendor’s multi-layered security approach appears to have stopped a more serious compromise.
The attackers had no access to the Dragos messaging system because it required administrator approval, and role-based access controls prevented them from compromising IT helpdesks, customer support data, employee recognition systems, sales leads, etc. .
Once the hacker was identified by the vendor’s security information and event management (SIEM) tool, compromised accounts were blocked and third-party incident response and MDR were enabled. Security controls prevented malicious attackers from lateral movement, privilege escalation, and persistent access or modification of the company’s infrastructure, Dragos said.
Unfortunately, not all ransomware victims have a similar experience. In a report yesterday, Sophos claimed that in 2022, 66% of his organizations will be hit by ransomware, with a staggering 76% of them having their data encrypted.